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IN THE CLAIMS 

1 1 . [currently amended] Method for monitoring of a communication link between a 

2 source network node and a destination network node, comprising 

3 - employing, on said communication link, the IPSec protocol for tunneling IP 

4 packets between the source network node and the destination network node, 

5 - transmitting an acknowledgement packet by the destination network node 4f-at 

6 | least when a second condition we-of a first condition and a second condition is 

7 fulfilled, said first condition being the reception of at least a predetermined number 

8 of IPSec packets after transmission of the previous acknowledgement packet, 

9 and said second condition being the reception of an IPSec packet via the 

1 0 communication link after a predetermined time has passed after transmission of 

1 1 the previous acknowledgement packet. 

1 2. [currently amended] Method for monitoring of a communication link between a 

2 source network node and a destination network node, comprising 

3 - employing, on said communication link, the IPSec protocol for tunneling 

4 IP packets between the source network node and the destination network node, 

5 - transmitting an acknowledgement packet by the destination network 

6 | node tf-at least when a second condition efte-of a first condition and a second 

7 condition is fulfilled, wherein said acknowledgement packet comprises at least the 

8 sequence number of the last received IPSec packet and at least one value 

9 corresponding to the amount of data received via the IPSec communication link, 
1 0 said first condition being the reception of at least a predetermined number of 

1 1 IPSec packets after transmission of the previous acknowledgement packet, and 

1 2 said second condition being the reception of a packet via the communication link 

1 3 after a predetermined time has passed after transmission of the previous 

1 4 acknowledgement packet. 

1 3. [original] A method according to claim 2, wherein said acknowledgement packet 

2 comprises at least a packet counter value indicating the number of packets received via 

3 the communication link. 
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1 4. [original] A method according to claim 2, wherein said acknowledgement packet 

2 comprises at least a byte counter value indicating the number of bytes received via the 

3 communication link. 

1 5. [original] A method according to claim 2, wherein said acknowledgement packet 

2 comprises at least a packet counter value indicating the number of packets received via 

3 the communication link and a byte counter value indicating the number of bytes received 

4 via the communication link. 

1 6. [original] A method according to claim 2, further comprising at least the step of 

2 determining the packet success rate of the communication link at least partly on the basis 

3 of information contained in an acknowledgement packet. 

1 7. [original] A method according to claim 2, further comprising at least the step of 

2 determining the throughput of the communication link at least partly on the basis of 

3 information contained in an acknowledgement packet. 

1 8. [currently amended] A method for measuring the performance of an IPSEC mon i tor i ng 

2 of a communication link between a source network node and a destination network node, 

3 comprising 

4 - employing, on said communication link, the IPSec protocol for tunneling IP 

5 packets between the source network node and the destination network node, 

6 - transmitting an acknowledgement packet by the destination network node 

7 | tf-at least when a second condition on e of a first condition and a second 

8 condition is fulfilled, 

9 said first condition being the reception of at least a predetermined 
1 0 number of IPSec packets after transmission of the previous 

1 1 acknowledgement packet, and 

1 2 said second condition being the reception of an IPSec packet via the 

1 3 communication link after a predetermined time has passed after 

1 4 transmission of the previous acknowledgement packet 

1 5 - storing of the sequence number and the transmission time of each IPSec 

1 6 packet transmitted from the source network node to the destination network 
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1 7 node in a memory means, and 

1 8 - determining the round trip time of the communication link on the basis of 

1 9 the reception time of an acknowledgement packet and the stored transmission 

2 0 time of the corresponding transmitted packet. 

1 9. [currently amended] Method for monitoring of a plurality of communication links 

2 between a source network site and a destination network site, each of the sites having 

3 at least one network node, 

4 in which method an active communication link is monitored and an inactive communication 

5 link is monitored, 

6 said method comprising at least the following steps for monitoring an active 

7 communication link between the source network site and the destination network site, the 

8 active communication link employing the IPSec protocol: 

9 the step of transmission of an acknowledgement packet by the destination 
1 0 | network node if-at least when a second condition ene-of a first condition and a 
1 1 second condition is fulfilled, 

1 2 said first condition being the reception of at least a predetermined number 

1 3 of IPSec packets after transmission of the previous acknowledgement 

1 4 packet, and 

1 5 said second condition being the reception of a packet via the 

1 6 communication link after a predetermined time has passed after transmission 

1 7 of the previous acknowledgement packet, 

1 8 and said method comprising at least the following steps for monitoring an inactive 

1 9 communication link between the source network site and the destination network site: 

2 0 - transmitting a probe packet from a source node at the source network site 
2 1 via said inactive communication link to a destination node at the destination 
2 2 network site, 

2 3 - storing the transmission time of said probe packet in a memory means, 

2 4 - transmitting a response packet from said destination node to said source 

2 5 node as a response to receiving a probe packet, 

2 6 - determining the round trip time of said inactive communication link from the 

2 7 difference of the reception time of the response packet and the stored 

2 8 transmission time of the corresponding probe packet 
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2 9 - maintaining present status of said active and inactive communications links 

3 0 or replacing said active communication link with said inactive communication link 
3 1 based on results of said monitoring. 

1 10. [original] A method according to claim 9, said method further comprising the steps 

2 of 

3 - transmitting a plurality of probe packets from said source node at the 

4 source network site via said inactive communication link to said destination node 

5 at the destination network site, 

6 - receiving response packets to said probe packets, and 

7 - determining the packet success rate of said inactive communication link 

8 from the number of said received response packets and the number of 

9 transmitted probe packets. 

1 11. [currently amended] A network node comprising at least 

2 - means for communicating over a IPSec protocol communication link 

3 with a second network node in order to tunnel IP packets transmitted to said 

4 second network node, 

5 - means for sending IPSec packets containing IP packets, 

6 - means for receiving acknowledgement packets for said IPSec 

7 packets, 

8 - means for obtaining a sequence number of an IPSec packet from a 

9 received acknowledgement packet, 

1 0 - means for obtaining a value from the acknowledgement packet, said 

1 1 value corresponding to the amount of data received via the communication 

1 2 link by the second network node, and 

1 3 - means for_determining the packet success rate of the communication 

1 4 link at least partly on the basis of said value. 

1 12. [original] A network node according to claim 1 1 , further comprising at least means 

2 determining the throughput of the communication link at least partly on the basis of said 

3 value. 
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1 13. [currently amended] A network node comprising at least 

2 - means foLCommunicating over a IPSec protocol communication link 

3 with a second network node in order to tunnel IP packets transmitted to said 

4 second network node, 

5 - means for sending IPSec packets containing IP packets, 

6 - means for receiving acknowledgement packets for said IPSec 

7 packets, 

8 - means for obtaining a sequence number of an IPSec packet from a 

9 received acknowledgement packet, 

1 0 - means for storing in a memory means the sequence number and the 

1 1 transmission time of each IPSec packet transmitted by the network node via 

1 2 the communication link, and 

1 3 - means fojLdetermining the round trip time of the communication link 

1 4 on the basis of the reception time of an acknowledgement packet and the 

1 5 stored transmission time of the corresponding transmitted packet. 

1 14. [currently amended] A network node comprising at least 

2 - means foLCommunicating over a IPSec protocol communication link 

3 with a second network node in order to tunnel IP packets transmitted from 

4 said second network node, 

5 - means foLsending IPSec packets containing IP packets, 

6 - means fortransmitting an acknowledgement packet tf^at least when 

7 a second conditio n one-of a first condition and a second condition is fulfilled, 

8 said first condition being the reception of at least a predetermined number 

9 of IPSec packets after transmission of the previous acknowledgement 
1 0 packet, and 

1 1 said second condition being the reception of a packet via the 

1 2 communication link after a predetermined time has passed after 

1 3 transmission of the previous acknowledgement packet. 

1 15. [currently amended] A network node comprising at least 

2 - means foLCommunicating over a IPSec protocol communication link 

3 with a second network node in order to tunnel IP packets transmitted from 
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4 said second network node, 

5 - means for receiving IPSec packets containing IP packets, 

6 - means for transmitting an acknowledgement packet tf^at least when 

7 a second condition ene-of a first condition and a second condition is fulfilled,- 

8 - means fonnserting a sequence number of a received IPSec packet 

9 and at least one value corresponding to the amount of data received via the 
1 0 communication link in said acknowledgement packet, 

1 1 said first condition being the reception of at least a predetermined 

1 2 number of IPSec packets after transmission of the previous 

1 3 acknowledgement packet, and 

1 4 said second condition being the reception of a packet via the 

1 5 communication link after a predetermined time has passed after transmission 

1 6 of the previous acknowledgement packet. 



1 16. [previously amended] A network node according to claim 15, said network node 

2 further comprising at least means inserting a packet counter value in said 

3 acknowledgement packet, said packet counter value indicating the number of packets 

4 received via the communication link. 



1 17. [previously amended] A network node according to claim 15, said network node 

2 further comprising at least means inserting a byte counter value in said 

3 acknowledgement packet, said byte counter value indicating the number of bytes 

4 received via the communication link. 



1 18. [currently amended] A network node comprising at least 

2 - means for communicating over a IPSec protocol communication link 

3 with a second network node in order to tunnel IP packets transmitted from 

4 said second network node, 

5 - means fortransmitting an acknowledgement packet tf-at least when 

6 a second condition ene-of a first condition and a second condition is fulfilled, 

7 said first condition being the reception of at least a predetermined number 

8 of IPSec packets after transmission of the previous acknowledgement 

9 packet, and 
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1 0 said second condition being the reception of a packet via the 

1 1 communication link after a predetermined time has passed after 

1 2 transmission of the previous acknowledgement packet, 

1 3 - means for sending IPSec packets, 

1 4 - means for receiving acknowledgement packets for said IPSec packets, 

1 5 - means for obtaining a sequence number of an IPSec packet from a 

1 6 received acknowledgement packet, 

1 7 - means for obtaining a value from the acknowledgement packet, said value 

1 8 corresponding to the amount of data received via the communication link by the 

1 9 second network node, and 

2 0 - means foLdetermining the packet success rate of the communication link 
2 1 at least partly on the basis of said value. 

1 19. [currently amended] Software program product comprising a computer readable 

2 medium containing computer-readable software program code for a network node for 

3 controlling said network node to communicate using commun i cat i ng w i th the IPSec 

4 protocol with a second network node via a communication link, said software program 

5 product code comprising at least 

6 - software program code for communicating over a IPSec protocol 

7 communication link with a second network node in order to tunnel IP packets 

8 transmitted from said second network node, 

9 - software program code fonreceiving IPSec packets containing IP 
1 0 packets, 

1 1 - software program code for transmitting an acknowledgement packet 

1 2 | tf^at least when a second condition one-of a first condition and a second 

1 3 condition is fulfilled, 

1 4 said first condition being the reception of at least a predetermined number 

1 5 of IPSec packets after transmission of the previous acknowledgement 

1 6 packet, and 

1 7 said second condition being the reception of a packet via the 

1 8 communication link after a predetermined time has passed after 

1 9 transmission of the previous acknowledgement packet, 

2 0 - software program code for receiving acknowledgement packets for 
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2 1 IPSec packets transmitted by the network node, 

2 2 - software program code for_obtaining a sequence number of an IPSec 

2 3 packet from a received acknowledgement packet, 

2 4 - software program code for obtaining a value from the 

2 5 acknowledgement packet, said value corresponding to the amount of data 

2 6 received via the communication link by the second network node, and 

2 7 - software program code for determining the packet success rate of the 

2 8 communication link at least partly on the basis of said value. 

1 20. [currently amended] Software program product comprising a computer 

2 readable medium containing computer-readable software program code for a network 

3 node for controlling said network node to communicate using Gommun i oat i ng -with* the 

4 IPSec protocol with a second network node via a communication link, said software 

5 program code produot comprising at least 

6 - software program code for communicating over a IPSec protocol 

7 communication link with a second network node in order to tunnel IP packets 

8 transmitted to said second network node, 

9 - software program code for sending IPSec packets containing IP packets, 

1 0 - software program code for receiving acknowledgement packets for said 

1 1 IPSec packets, 

1 2 - software program code foiiobtaining a sequence number of an IPSec 

1 3 packet from a received acknowledgement packet, 

1 4 - software program code for storing in a memory means the sequence 

1 5 number and the transmission time of each IPSec packet transmitted by the 

1 6 network node via the communication link, and 

1 7 - software program code for determining the round trip time of the 

1 8 communication link on the basis of the reception time of an acknowledgement 

1 9 packet and the stored transmission time of the corresponding transmitted 

2 0 packet. 

1 21. [allowed] Method for monitoring of a communication link between a source network 

2 node and a destination network node, comprising 

3 - employing, on said communication link, the IPSec protocol for tunneling IP 
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4 packets of one or more TCP/IP connections between the source network node 

5 and the destination network node, 

6 - transmitting, separately from TCP retransmission scheme carried out on 

7 said one or more TCP/IP connections, an acknowledgement packet by the 

8 destination network node if at least one of a first condition and a second 

9 condition is fulfilled, 

1 0 said first condition being the reception of at least a predetermined number 

1 1 of IPSec packets after transmission of the previous acknowledgement 

1 2 packet, and 

1 3 said second condition being the reception of an IPSec packet via the 

1 4 communication link after a predetermined time has passed after 

1 5 transmission of the previous acknowledgement packet. 

1 22. [allowed] A method according to claim 21 , comprising tunneling IP packets of two or 

2 more TCP/IP connections by means of said communication link using the IPSec protocol. 
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